We have a back to back ISA server DMZ configuration. We run 3 internal ISA servers for 3 separate internal networks, Corporate, Education, and Public Library. The DMZ has a single connection to the internet. Each internal network has different content filtering requirements so the content filtering is installed on each internal ISA server. Some of our more technically able users are bypassing the content filtering by configuring Internet Explorer to use the uptstream ISA server IP address and using the firewall client to reach the upstream ISA server. Is there a configuration which can prevent this? Our users will still need to access some content using the firewall client. Andy Greenhalgh